Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Munin could be made to overwrite files.. =========================================================================Ubuntu Security Notice USN-3215-1 March 02, 2017 munin vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: Munin could be made to overwrite files. Software Description: - munin: Network-wide graphing framework Details: It was discovered that Munin incorrectly handled CGI graphs. A remote attacker could use this issue to overwrite arbitrary files as the www-data user. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: munin 2.0.19-3ubuntu0.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3215-1 CVE-2017-6188 Package Information: https://launchpad.net/ubuntu/+source/munin/2.0.19-3ubuntu0.2 . A vulnerability found in Munin may lead to unauthorized file overwrites. To safeguard against this potential remote exploit, it is advisable to upgrade your Ubuntu system.. munin security, ubuntu update, file overwrite, remote attack, cgi vulnerability. . LinuxSecurity.com Team
An update for golang is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: golang security, bug fix, and enhancement update Advisory ID: RHSA-2016:1538-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2016:1538.html Issue date: 2016-08-02 CVE Names: CVE-2016-5386 ==================================================================== 1. Summary: An update for golang is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server Optional (v. 7) - noarch, x86_64 3. Description: The golang packages provide the Go programming language compiler. The following packages have been upgraded to a newer upstream version: golang (1.6.3). (BZ#1346331) Security Fix(es): * An input-validation flaw was discovered in the Go programming language built in CGI implementation, which set the environment variable "HTTP_PROXY" using the incoming "Proxy" HTTP-request header. The environment variable "HTTP_PROXY" is used by numerous web clients, including Go's net/http package, to specify a proxy server to use for HTTP and, in some cases, HTTPS requests. This meant that when a CGI-based web application ran, an attacker could specify a proxy server which the application then used for subsequent outgoing requests, allowinga man-in-the-middle attack. (CVE-2016-5386) Red Hat would like to thank Scott Geary (VendHQ) for reporting this issue. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1346331 - REBASE to golang 1.6 1353798 - CVE-2016-5386 Go: sets environmental variable based on user supplied Proxy request header 6. Package List: Red Hat Enterprise Linux Server Optional (v. 7): Source: golang-1.6.3-1.el7_2.1.src.rpm noarch: golang-docs-1.6.3-1.el7_2.1.noarch.rpm golang-misc-1.6.3-1.el7_2.1.noarch.rpm golang-src-1.6.3-1.el7_2.1.noarch.rpm golang-tests-1.6.3-1.el7_2.1.noarch.rpm x86_64: golang-1.6.3-1.el7_2.1.x86_64.rpm golang-bin-1.6.3-1.el7_2.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2016-5386 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2016 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFXoRzhXlSAg2UNWIIRApixAKCMAuZK86IigGI6xma0zpDy/0sQRwCgkeda Hk4/rr0WJ77ZzBLkEBO5tQI=Ksfa -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
Get the latest Linux and open source security news straight to your inbox.